>> Linux Kernel Security Update Fixes Multiple Denial of Service Vulnerabilities
Title : Linux Kernel Security Update Fixes Multiple Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-2466 CVE ID : CVE-2007-3107 - CVE-2007-3642
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-09
Technical Description
Two vulnerabilities have been identified in Linux Kernel, which could be exploited by attackers to cause a denial of service.
The first issue is caused by an error in the "decode_choice()" [net/netfilter/nf_conntrack_h323_asn1.c] function when handling malformed Choices that are still encoded in the fixed length bit-field, which could be exploited by attackers to cause an access to undefined types, creating a denial of service condition.
The second vulnerability is caused by an error in the signal handling on PowerPC-based systems, which could be exploited by malicious local attackers to crash an affected system, creating a denial of service condition.